Try our new research platform with insights from 80,000+ expert users

FortiWeb Web Application Firewall (WAF) vs Prisma Cloud by Palo Alto Networks comparison

 

Comparison Buyer's Guide

Executive Summary
 

Categories and Ranking

FortiWeb Web Application Fi...
Ranking in Web Application Firewall (WAF)
17th
Average Rating
8.2
Number of Reviews
21
Ranking in other categories
No ranking in other categories
Prisma Cloud by Palo Alto N...
Ranking in Web Application Firewall (WAF)
5th
Average Rating
8.4
Reviews Sentiment
7.4
Number of Reviews
106
Ranking in other categories
Container Security (1st), Cloud Workload Protection Platforms (CWPP) (1st), Cloud Security Posture Management (CSPM) (1st), Cloud-Native Application Protection Platforms (CNAPP) (1st), Data Security Posture Management (DSPM) (1st)
 

Mindshare comparison

As of October 2024, in the Web Application Firewall (WAF) category, the mindshare of FortiWeb Web Application Firewall (WAF) is 0.6%, up from 0.1% compared to the previous year. The mindshare of Prisma Cloud by Palo Alto Networks is 2.5%, up from 2.4% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Web Application Firewall (WAF)
 

Featured Reviews

Nitith Unarat - PeerSpot reviewer
May 13, 2024
Identifies potential DDoS attacks and suspicious domain activity
My company is a Fortinet partner and specializes in FortiWeb. We often compete against cloud-native solutions like Azure Application Gateway WAF. We typically conduct proof-of-concept tests for potential clients. They are usually looking for API protection and bot mitigation, which FortiWeb excels…
VISHWJEET GAIKWAD - PeerSpot reviewer
Aug 21, 2024
Works very well for multi-cloud environments and is more cost-effective than cloud-native tools
Some of the clients onboard individual cloud accounts into Prisma Cloud. When any new service comes into the AWS, Azure, or any other cloud, Prisma Cloud generates a warning about the new service and any missing permissions to be able to ingest the logs. We then manually run a Terraform template for Azure or a CFT template for AWS. It is a manual task that we have to do as and when needed. It is a repetitive and manual task. They should find a way to automatically update the role with the CFT or Terraform template. It would be best if this task is automated. When an account is onboarded, if it is missing any permission, it should automatically be updated with the required permissions and policies. If they can do something from the AI security perspective, it will be helpful. I am not sure if it has any AI capabilities, but it would be helpful to have AI integration for finding out issues and remediating alerts.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"We use it to secure VMs and applications. It protects against DDoS attacks. It's very user-friendly."
"FortiWeb Web Application Firewall blocks attacks from application layers and provides protection."
"The initial setup was easy since it was possible to get remote support for the product."
"The fact that I can log into the platform and see everybody, see logs, authentication failure, and see everything on one platform, is the most valuable feature."
"It improves latency by optimizing traffic routing."
"The tool's HTTP traffic, website fixing, and blocking are fantastic. It is user-friendly with easy configuration."
"The product is easy to configure."
"FortiWeb identified potential DDoS attacks and suspicious domain activity, showcasing the value of its machine-learning capabilities."
"I like Palo Alto's threat protection and Wi-Fi coverage. It has advanced features like DNS security and sandboxing. The automation capabilities are excellent."
"It provides good visibility and control regardless of the complexity."
"The two most valuable features are container security and the capability to discover workloads."
"The Cloud Workload Protection module is a very strong solution. I like the Cloud Workload Protection part. It is something I have not used for the banking client, but I had a chance to try it out for roughly a month on actual deployment of another customer. That part was really robust. Cloud Workload Protection would be the main feature that I enjoy the most."
"The solution offers very good configuration capabilities."
"The dynamic workload identity creation, attestation, and assignment is the best feature. In addition, the application dependency map across heterogeneous environments for compliance is a striking feature."
"The solution's dashboard looks very user-friendly."
"Due to the maturity of most companies, security posture management is the most valuable feature."
 

Cons

"The documentation is poor."
"FortiWeb could have an inbound load balancing pack."
"We have encountered issues with webhooks and management of FortiWeb Web Application Firewall's on-premise version."
"There is room for improvement in the support. The response time could be faster. Plus, they ask for a lot of information. It is not easy to get support."
"The price is a little higher than the competitors."
"It would be good if the solution integrated with other solutions, like SAP."
"FortiWeb Web Application Firewall's signature database updates could be improved."
"FortiWeb Web Application Firewall needs to improve its performance."
"They need to make the settings more flexible to fit our internal policies about data. We didn't want developers to see some data, but we wanted them to have access to the console because it was going to help them... It was a pain to have to set up the access to some languages and some data."
"In terms of securing cloud-native development at build time, a lot of improvement is needed. Currently, it's more a runtime solution than a build-time solution. For runtime, I would rate it at seven out of 10, but for build-time there is a lot of work to be done."
"Prisma could improve the data quality. One challenge is that when an application is deployed on multiple virtual machines, we get an alert for each machine, but the biggest challenge is container flapping. When containers go up and down, we get 100 alerts on one day, but it reports 20 the next day. The numbers keep changing, and the app owners tell us, "You reported a hundred vulnerabilities from my app, and today, you report 20. I haven't made any changes in production, so is your data correct or not?""
"The licensing is a bit confusing."
"The access controls for our bank roles were not granular enough. We needed specific people to do particular actions, and we often had to give some people way too much access for them to be able to do what they needed in Prisma. They couldn't do their jobs if they didn't have that level of access, so other people had to do that part for them. It would help to have more granular role-based access controls."
"The Application Security dashboard was not as user-friendly as the Cloud Security dashboard."
"The alignment of Twistlock Defender agents with image repositories needs improvement. These deployed agents have no way of differentiating between on-premise and cloud-based image repositories. If I deploy a Defender agent to secure an on-premise Kubernetes cluster, that agent also tries to scan my ECR image repositories on AWS. So, we have limited options for aligning those Defenders with the repositories that we want them to scan. It is scanning everything rather than giving us the ability to be real granular in choosing which agents can scan which repositories."
"The cloud integration is too complex. It should be simple to integrate Prisma Cloud with any cloud environment. Policy management could also be simpler."
 

Pricing and Cost Advice

"FortiWeb Web Application Firewall is not expensive."
"FortiWeb Web Application Firewall's pricing is suited for small or medium organizations."
"I rate the product price a four on a scale of one to ten, where one is a high price, and ten is a low price."
"The product provides very good prices to customers. The price is set well and offers great value for money."
"This product offers two pricing options: a standard package and an advanced package."
"I rate the tool's pricing an eight out of ten."
"I would rate the pricing a four out of ten."
"It is a cheap solution."
"The product is very expensive, but the cost is a necessary evil; I don't know how we could have any kind of cloud presence without this type of monitoring. The pricing is calculated by module and resource usage. Ultimately, it saves us money in the amount of time we would spend uncovering what it uncovers, and we might not make the required discoveries without it anyway. Prisma offers incredible value, though I wish it were cheaper."
"One thing we're very pleased about is how the licensing model for Prisma is based on work resources. You buy a certain amount of work resources and then, as they enable new capabilities within Prisma, it just takes those work resource units and applies them to new features. This enables us to test and use the new features without having to go back and ask for and procure a whole new product, which could require going through weeks, and maybe months, of a procurement process."
"The cost depends on the pricing model. Compared to other solutions, the cost isn't that bad."
"Prisma Cloud is more expensive than Check Point CloudGuard."
"The purchasing process was easy and quick. It is a very economical solution."
"If a competitor came along and said, "We'll give you half the price," that doesn't necessarily mean that's the right answer, at all. We wouldn't necessarily entertain it that way. Does it do what we need it to do? Does it work with the things that we want it to work with? That is the important part for us. Pricing wasn't the big consideration it might be in some organizations. We spend millions on public cloud. In that context, it would not make sense to worry about the small price differences that you get between the products."
"The licensing cost is a bit high on the compute side."
"The cost was not on the higher side. Overall, the cost gets recovered with its implementation."
report
Use our free recommendation engine to learn which Web Application Firewall (WAF) solutions are best for your needs.
813,161 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
16%
Computer Software Company
12%
Manufacturing Company
12%
Educational Organization
6%
Educational Organization
16%
Computer Software Company
13%
Financial Services Firm
13%
Manufacturing Company
9%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about FortiWeb Web Application Firewall (WAF)?
The most valuable features of the solution are SD-WAN, filtration, web filter, application filter, and IPS.
What is your experience regarding pricing and costs for FortiWeb Web Application Firewall (WAF)?
The product provides very good prices to customers. The price is set well and offers great value for money.
What needs improvement with FortiWeb Web Application Firewall (WAF)?
Regarding areas for improvement, the documentation needs work. We had issues with a customer because the documentation didn't clearly show which devices can connect with FortiWeb WAF, leading to mi...
What is your primary use case for Prisma Cloud by Palo Alto Networks ?
Prisma Cloud helps support DevSecOps methodologies, making those responsibilities easier to manage.
What Cloud-Native Application Protection Platform do you recommend?
We like Prisma Cloud by Palo Alto Networks, since it offers us incredible visibility into our entire cloud system. We are able to easily see where our container vulnerabilities lie and and where cl...
What do you think of Aqua Security vs Prisma Cloud?
Aqua Security is easy to use and very manageable. Its main focus is on Kubernetes and Docker. Security is a very valuable feature and their speed of integration is very good. The initial setup was ...
 

Also Known As

No data available
Palo Alto Networks Prisma Cloud, Prisma Public Cloud, RedLock Cloud 360, RedLock, Twistlock, Aporeto
 

Overview

 

Sample Customers

Information Not Available
Amgen, Genpact, Western Asset, Zipongo, Proofpoint, NerdWallet, Axfood, 21st Century Fox, Veeva Systems, Reinsurance Group of America
Find out what your peers are saying about FortiWeb Web Application Firewall (WAF) vs. Prisma Cloud by Palo Alto Networks and other solutions. Updated: October 2024.
813,161 professionals have used our research since 2012.